There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30 that allows a remote, unauthenticated attacker to potentially entice a user to click a link that causes arbitrary HTML to render in a victim's browser. There is no evidence of JavaScript execution, which limits the impact. At the time of submission, ArcGIS Web App Builder developer edition is retired and unsupported. ArcGIS Web App Builder 2.30 is not susceptible to this vulnerability.
History

Fri, 19 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 19 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Description There is an HTML injection issue in Esri ArcGIS Web AppBuilder developer edition versions prior to 2.30 that allows a remote, unauthenticated attacker to potentially entice a user to click a link that causes arbitrary HTML to render in a victim's browser. There is no evidence of JavaScript execution, which limits the impact. At the time of submission, ArcGIS Web App Builder developer edition is retired and unsupported. ArcGIS Web App Builder 2.30 is not susceptible to this vulnerability.
Title HTML injection issue in ArcGIS Web App Builder
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Esri

Published:

Updated: 2025-12-19T20:43:36.827Z

Reserved: 2025-12-10T17:22:04.791Z

Link: CVE-2025-67712

cve-icon Vulnrichment

Updated: 2025-12-19T20:43:07.299Z

cve-icon NVD

Status : Received

Published: 2025-12-19T20:15:55.450

Modified: 2025-12-19T20:15:55.450

Link: CVE-2025-67712

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.